mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Dec 31, 2005 |
| Apache Httpd 2_0_x Mod_ssl Access Control Dos | — | — | Aug 16, 2010 | Dec 31, 2005 |
| Apple Osx Apache | — | Apply OS X security update 2008-003 | Dec 16, 2011 | Dec 31, 2005 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Dec 31, 2005 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Dec 31, 2005 |
| Suse | — | Upgrade apache2-preforkUpgrade apache2Upgrade apache2-manualUpgrade apache2-workerUpgrade apache2-develUpgrade apache2-eventUpgrade apache2-utils | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade apache2-mpm-worker | Nov 8, 2024 | Dec 31, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub